Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Data Breaches » ASUS Warns Customers After eShop Security Breach Exposes Order Data

ASUS Warns Customers After eShop Security Breach Exposes Order Data

By:
Last updated:September 24, 2026
Human Written
  • ASUS warned eShop customers after unauthorized access affected part of its online store and may have exposed contact details and order records.

  • The company said payment cards, bank accounts and other financial information were not involved in the incident.

  • ASUS has not reported any known misuse, but warned that exposed information could support convincing phishing emails, texts and phone calls.

ASUS Warns Customers After Unauthorized Access Exposes eShop Order Data

ASUS has warned some eShop customers about unauthorized access to part of its online store. The breach has probably compromised customer records and order information on purchases.

ASUS claims that, as of now, it does not see any signs of harm from unauthorized access. However, the company warns that criminals can use the leaked information to compose messages or calls connected to orders from customers.

Unauthorized Access Hits ASUS eShop

The security incident affected part of the ASUS eShop environment. ASUS said its investigation found that certain customer order information may have been accessed. The affected information includes contact details and order records.

ASUS has not specified the exact number of affected customers. It has also not been revealed when the breach really happened. It has not identified the attacker or explained the specific method used to enter the affected environment.

ASUS said it acted after identifying the issue. The company contained the incident and added further security measures around the affected systems. Its investigation remains ongoing.

Also, ASUS said it had found no evidence that the unauthorized access continued after the company took action. The breach notice appears to focus on information connected with eShop transactions. That makes the incident different from a reported compromise involving ASUS hardware, firmware or wider company systems.

Financial Information Was Not Involved

One important detail concerns the type of information exposed. ASUS said payment card details, bank account information and other financial information did not form part of the incident.

That means the available report does not indicate that attackers obtained the payment information of customers through the eShop breach. The company has instead identified customer contact details and order records as information that may have been accessed.

This distinction matters because order records can still contain useful information for scammers. A separate reported case also highlights the risks surrounding ASUS-related data exposure. Threat actor claims 1TB of data linked to ASUS is for sale on dark web covers an alleged large-scale data sale involving information linked to the company.

A criminal may not need payment details to make a fraudulent message appear genuine. For example, an attacker could refer to a recent ASUS purchase in an email. The message could mention an order, delivery issue or product service to make the request look familiar.

ASUS has not said that criminals have already used the information in this way. At the time of its notification, the company said it was unaware of misuse or harm involving affected customers. The number of affected users also remains unclear. The customer notice does not provide a specific figure or a complete list of affected regions.

Phishing Risk Raises Concern

The main concern for customers now involves phishing and other forms of social engineering. Criminals can use ordinary personal details to make fake messages appear connected to a real transaction.

ASUS warned that the exposed information could support convincing emails, text messages and telephone calls. Such messages could refer to ASUS products, services or orders.

For instance, a fake message could claim that an order needs confirmation. Another could ask a customer to update delivery details or resolve a payment problem. Nevertheless, customers should not presume a message is genuine just because it has the correct details about ordering. Criminals can use stolen information to make their correspondence seem beyond suspicion.

This means customers should be careful with unexpected messages related to ASUS. They should refrain from opening links that are not from trusted sources – and also from giving passwords, verification codes, and other confidential information to unverified senders.

ASUS already cautions customers against fake websites, emails and other communication means purporting to be from the company. Its security guidance advises users to remain cautious and use official ASUS channels when checking suspicious communications.

What ASUS Customers Should Do Now

Customers who receive an unexpected message about an ASUS order should verify it independently. They can open the official ASUS website rather than following a link contained in an email or text message. ASUS provides customer support channels through its official website. Its eShop also allows customers to check order information through their accounts, depending on the relevant regional store.

Meanwhile, users should keep an eye on messages that mention recent purchases or delivery activity. They should pay particular attention to requests for login information, payment details or urgent action.

ASUS has not reported any known misuse from this incident. Still, that position reflects the company’s findings at the time of its notification and does not remove the need for caution. The company said it has taken additional measures to secure the affected systems. Its investigation will determine more about the incident and its possible impact.

The breach reveals the need to safeguard consumer order data. Names may not lead to account information, but criminals can exploit them to commit fraud. For ASUS customers, there is no news of any lost payment information. Instead, the emphasis now is on how to prevent the offenders from using exposed order information to make fraudulent transactions.

While the investigations are underway, ASUS might disclose more information regarding the compromised systems and clients. Meanwhile, it is best that customers check any unsolicited messages that may relate to ASUS with verified contacts of the company.

ASUS has warned some eShop customers about unauthorized access to part of its online store. The breach has probably compromised customer records and order information on purchases.

ASUS claims that, as of now, it does not see any signs of harm from unauthorized access. However, the company warns that criminals can use the leaked information to compose messages or calls connected to orders from customers.

Unauthorized Access Hits ASUS eShop

The security incident affected part of the ASUS eShop environment. ASUS said its investigation found that certain customer order information may have been accessed. The affected information includes contact details and order records.

ASUS has not specified the exact number of affected customers. It has also not been revealed when the breach really happened. It has not identified the attacker or explained the specific method used to enter the affected environment.

ASUS said it acted after identifying the issue. The company contained the incident and added further security measures around the affected systems. Its investigation remains ongoing.

Also, ASUS said it had found no evidence that the unauthorized access continued after the company took action. The breach notice appears to focus on information connected with eShop transactions. That makes the incident different from a reported compromise involving ASUS hardware, firmware or wider company systems.

Financial Information Was Not Involved

One important detail concerns the type of information exposed. ASUS said payment card details, bank account information and other financial information did not form part of the incident.

That means the available report does not indicate that attackers obtained the payment information of customers through the eShop breach. The company has instead identified customer contact details and order records as information that may have been accessed.

This distinction matters because order records can still contain useful information for scammers. A criminal may not need payment details to make a fraudulent message appear genuine. For example, an attacker could refer to a recent ASUS purchase in an email. The message could mention an order, delivery issue or product service to make the request look familiar.

ASUS has not said that criminals have already used the information in this way. At the time of its notification, the company said it was unaware of misuse or harm involving affected customers. The number of affected users also remains unclear. The customer notice does not provide a specific figure or a complete list of affected regions.

Phishing Risk Raises Concern

The main concern for customers now involves phishing and other forms of social engineering. Criminals can use ordinary personal details to make fake messages appear connected to a real transaction.

ASUS warned that the exposed information could support convincing emails, text messages and telephone calls. Such messages could refer to ASUS products, services or orders.

For instance, a fake message could claim that an order needs confirmation. Another could ask a customer to update delivery details or resolve a payment problem. Nevertheless, customers should not presume a message is genuine just because it has the correct details about ordering. Criminals can use stolen information to make their correspondence seem beyond suspicion.

This means customers should be careful with unexpected messages related to ASUS. They should refrain from opening links that are not from trusted sources – and also from giving passwords, verification codes, and other confidential information to unverified senders.

ASUS already cautions customers against fake websites, emails, and other communication means purporting to be from the company. Its security guidance advises users to remain cautious and use official ASUS channels when checking suspicious communications.

What ASUS Customers Should Do Now

Customers who receive an unexpected message about an ASUS order should verify it independently. They can open the official ASUS website rather than following a link contained in an email or text message. ASUS provides customer support channels through its official website. Its eShop also allows customers to check order information through their accounts, depending on the relevant regional store.

Meanwhile, users should keep an eye on messages that mention recent purchases or delivery activity. They should pay particular attention to requests for login information, payment details or urgent action.

ASUS has not reported any known misuse from this incident. Still, that position reflects the company’s findings at the time of its notification and does not remove the need for caution. The company said it has taken additional measures to secure the affected systems. Its investigation will determine more about the incident and its possible impact.

The breach reveals the need to safeguard consumer order data. Names may not lead to account information, but criminals can exploit them to commit fraud. For ASUS customers, there is no news of any lost payment information. Instead, the emphasis now is on how to prevent the offenders from using exposed order information to make fraudulent transactions.

While the investigations are underway, ASUS might disclose more information regarding the compromised systems and clients. Meanwhile, it is best that customers check any unsolicited messages that may relate to ASUS with verified contacts of the company.

Share this article

About the Author

Joahn G

Joahn G

Cyber Threat Journalist

Joahn is a cyber threat journalist dedicated to tracking the evolving landscape of digital risks. His reporting focuses on ransomware gangs, data breach incidents, and state-sponsored cyber operations. By analyzing threat actor motives and tactics, he provides timely intelligence that helps readers understand and anticipate the security challenges of tomorrow.

View all posts by Joahn G >
Comments (0)

No comments.